FloodDefender: Protecting Data and Control Plane Resources under SDN-aimed DoS Attacks

被引:0
|
作者
Shang, Gao [1 ]
Zhe, Peng [1 ]
Bin, Xiao [1 ]
Aiqun, Hu [2 ]
Kui, Ren [3 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Southeast Univ, Sch Informat Sci & Engn, Nanjing, Jiangsu, Peoples R China
[3] Univ Buffalo State Univ New York, Dept Comp Sci & Engn, Buffalo, NY USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks
    Wang, Song
    Chandrasekharan, Sathyanarayanan
    Gomez, Karina
    Kandeepan, Sithamparanathan
    Al-Hourani, Akram
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [2] Combined Control and Data Plane Robustness of SDN Networks against Malicious Node Attacks
    Santos, Dorabella
    de Sousa, Amaro
    Machuca, Carmen Mas
    2018 14TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2018, : 54 - 62
  • [3] Networked Control Under DoS Attacks: Tradeoffs Between Resilience and Data Rate
    Feng, Shuai
    Cetinkaya, Ahmet
    Ishii, Hideaki
    Tesi, Pietro
    De Persis, Claudio
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2021, 66 (01) : 460 - 467
  • [4] Input-output data based tracking control under DoS attacks
    Yin, Liyuan
    Xu, Lezhong
    Zhu, Hongming
    Zhu, Yupeng
    Wu, Chengwei
    INTERNATIONAL JOURNAL OF CONTROL, 2024, 97 (07) : 1627 - 1637
  • [5] Adaptive control of networked control systems under DoS attacks
    Wang, Mengting
    Shi, Linshan
    Liu, Rong
    Liu, Shihan
    Systems Science and Control Engineering, 2024, 12 (01):
  • [6] Sampled-data resilient control for stochastic nonlinear CPSs under DoS attacks
    Liu, Xiaohua
    Deng, Feiqi
    Zeng, Pengyu
    Gao, Xiaobin
    Zhao, Xueyan
    INTERNATIONAL JOURNAL OF SYSTEMS SCIENCE, 2023, 54 (05) : 1165 - 1171
  • [7] Security Analysis and Control Under Periodic DoS Attacks
    Yin, Liyuan
    Xu, Lezhong
    Hou, Fusheng
    Zhu, Hongming
    Jing, Houhua
    Sun, Xingjian
    Wu, Chengwei
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (05): : 8473 - 8484
  • [8] Packet filtering for congestion control under DoS attacks
    Hu, YH
    Choi, HS
    Choi, HA
    SECOND IEEE INTERNATIONAL INFORMATION ASSURANCE WORKSHOP, PROCEEDINGS, 2004, : 3 - 18
  • [9] Enhancing security of SDN focusing on control plane and data plane
    Celesova, Barbora
    Val'ko, Jozef
    Grezo, Rudolf
    Helebrandt, Pavol
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [10] Resilient quantized control for asynchronous sampled-data networked control systems under DoS attacks
    Zhang, Xiaodan
    Xiao, Feng
    Wang, Aiping
    Mu, Bingxian
    SYSTEMS & CONTROL LETTERS, 2023, 179